fix: handle x-forwarded-host and proxy issues behind Cloudflare (#370)

This commit is contained in:
Matt
2026-02-08 16:59:01 -04:00
committed by GitHub
parent 008b5fd1a0
commit 08ba965921
2 changed files with 25 additions and 7 deletions

View File

@@ -13,6 +13,23 @@ const authHandler = toNodeHandler(auth.handler);
export default withRateLimit( export default withRateLimit(
{ points: 100, duration: 60 }, { points: 100, duration: 60 },
async (req, res) => { async (req, res) => {
/**
* Better-auth behind proxies (Nginx/Cloudflare) can sometimes fail to parse the protocol
* if headers are incorrectly set or if there are multiple values in X-Forwarded-Proto.
* We sanitize these headers here to ensure better-auth gets a clean protocol and host.
*/
const forwardedProto = req.headers["x-forwarded-proto"];
if (forwardedProto) {
const p = Array.isArray(forwardedProto) ? forwardedProto[0] : forwardedProto;
req.headers["x-forwarded-proto"] = p?.split(",")[0]?.trim();
}
const forwardedHost = req.headers["x-forwarded-host"];
if (forwardedHost) {
const h = Array.isArray(forwardedHost) ? forwardedHost[0] : forwardedHost;
req.headers["host"] = h?.split(",")[0]?.trim();
}
return await authHandler(req, res); return await authHandler(req, res);
}, },
); );

View File

@@ -11,15 +11,16 @@ import { createPlugins } from "./plugins";
import { configuredProviders } from "./providers"; import { configuredProviders } from "./providers";
export const initAuth = (db: dbClient) => { export const initAuth = (db: dbClient) => {
const baseURL = env("NEXT_PUBLIC_BASE_URL") || env("BETTER_AUTH_URL");
const trustedOrigins = env("BETTER_AUTH_TRUSTED_ORIGINS")?.split(",") ?? [];
return betterAuth({ return betterAuth({
secret: env("BETTER_AUTH_SECRET"), secret: env("BETTER_AUTH_SECRET"),
baseURL: env("NEXT_PUBLIC_BASE_URL"), baseURL,
trustedOrigins: env("BETTER_AUTH_TRUSTED_ORIGINS") trustedOrigins: [
? [ ...(baseURL ? [baseURL] : []),
env("NEXT_PUBLIC_BASE_URL") ?? "", ...trustedOrigins,
...(env("BETTER_AUTH_TRUSTED_ORIGINS")?.split(",") ?? []), ],
]
: [env("NEXT_PUBLIC_BASE_URL") ?? ""],
database: drizzleAdapter(db, { database: drizzleAdapter(db, {
provider: "pg", provider: "pg",
schema: { schema: {